fix(tauri): bind elevated scripts to catalog authority

Preserve required UAC elevation for game_setup.cmd, game_start.cmd, and server_start.cmd through a fixed-role elevated launcher worker. The worker reloads and matches embedded catalog authority, verifies the exact script from a no-follow locked handle, resolves System32 cmd.exe, and transfers path locks into the command process.

Setup still waits for completion; game and server return after the verified handoff while their command process retains the locks. Unmanifested, changed, reparse-backed, markerless, and streamed-only scripts fail closed.

Test Plan:
- just test
- just clippy
- just frontend-test
- just build-fixture
- nine Linux-visible authority/parser/digest tests
- Windows-only lock-transfer test added but not run (no Windows target/runtime available)
- git diff --check
This commit is contained in:
ddidderr committed 2026-09-12 13:10:36 +02:00
1 parent 42cf98ecec
commit 67ea355599
6 files changed
+1491 -170

No files matched your search

@@ -24,6 +24,7 @@ lanspread-peer = { path = "../../lanspread-peer" }
# external
base64 = { workspace = true }
blake3 = { workspace = true }
cap-fs-ext = { workspace = true }
cap-primitives = { workspace = true }
eyre = { workspace = true }
@@ -53,7 +54,14 @@ tauri-build = { version = "2", features = [] }
tokio = { workspace = true }
[target."cfg(windows)".dependencies]
windows = { workspace = true, features = ["Win32_Storage_FileSystem"] }
windows = {
workspace = true,
features = [
"Win32_Security",
"Win32_Storage_FileSystem",
"Win32_System_SystemInformation",
]
}
[lints.clippy]
needless_pass_by_value = "allow"